Security
Everything on this page is something we actually operate. There are no badges on it, because we have not earned any, and a badge would be the least informative thing here anyway.
In place today
What we do
Seven things, each of which is running in production right now and can be checked.
Your audio is reachable only through signed links
Untrusted audio is decoded in a sandbox
Staff can't listen to your audio
Every internal read of your data is recorded
Dangerous operations need a second look
Backups are encrypted, and restoring them is drilled weekly
Dependencies and the host are patched on a cadence
Disclosure
Reporting something
Email security@euphonaai.com. Tell us what you found and how to reproduce it; you do not need a proof-of-concept exploit and we would rather you did not build one against live data.
We will acknowledge within three working days and tell you what we are doing. We will not threaten you, and we will credit you if you want to be credited. There is no bounty programme — if one appears it will be on this page rather than negotiated by email.
Please do not access another person’s data, degrade the service for anyone else, or hold a finding for leverage. The machine-readable version of this is at /.well-known/security.txt.